CVE-2025-41078

HIGH

Viafirma Documents < 3.7.139 - Authenticated Privilege Escalation and Data Access via Authorization Bypass

Title source: llm
STIX 2.1

Description

Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of documents.

Scores

CVSS v3 8.1
EPSS 0.0021
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-863
Status published
Products (2)
viafirma/documents < 3.7.139
viafirma/documents_compose < 1.9.2
Published Jan 12, 2026
Tracked Since Feb 18, 2026